BitSight TRACE reported that off-brand H96 Android TV streaming boxes were used in a large ad-fraud and residential-proxy operation linked to Zhejiang Fengwo IoT Technology Co., Ltd., also known as Fengwo Group. Researcher Pedro Falé gained visibility into the activity by registering an expired domain previously used by the devices for telemetry, exposing tens of thousands of boxes that spoofed themselves as mobile phones from brands including Samsung, Vivo, Huawei, and Xiaomi. The devices allegedly ran two Fengwo-linked apps that coordinated fake ad clicks against AI-generated websites built to serve ads only to the spoofed mobile identities.
BitSight estimated that about 38,000 devices were contacting one observed Fengwo domain and that the ad-fraud component alone could produce nearly $50,000 per day, not including revenue from proxy services. The report also described the broader Fuyao Enterprise as an Android TV botnet supporting ad fraud at scale, with references to more than 120,000 AI digital humans used in the scheme. Researchers said the boxes switched roles depending on use, acting as residential proxies while the TV was on and performing ad-fraud tasks while it was off, underscoring the privacy, botnet, and supply-chain risks posed by insecure generic streaming devices.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
4 events from the most recent confirmed update back to the earliest known activity.
The FBI issued a Public Service Announcement warning that compromised home-network IoT devices are being used in the BADBOX 2.0 botnet for criminal activity, including residential proxy services. The PSA said the botnet spans millions of infected devices such as TV streaming boxes, projectors, infotainment systems, and digital picture frames, and provided indicators of compromise and mitigation guidance.
A BitSight TRACE report described the 'Fuyao Enterprise' as a hidden Android TV botnet used for large-scale ad fraud. The referenced reporting said the operation used more than 120,000 AI digital humans to support the scheme.
Bitsight TRACE attributed the ad fraud and residential proxy ecosystem involving generic H96 Android TV boxes to Zhejiang Fengwo IoT Technology Co., Ltd., also known as Fengwo Group. The report said apps on the devices coordinated fake ad clicks against AI-generated websites and that the boxes alternated between proxy use and ad fraud activity.
Bitsight TRACE researcher Pedro Falé gained visibility into the operation by registering an expired domain previously used by the devices for telemetry. This exposed tens of thousands of H96 Android TV boxes spoofing mobile phone identities and communicating with the infrastructure.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
8 references tracked. Mallory keeps watching after this page renders.
scworld.com
Open sourcethehackernews.com
Open sourcehelpnetsecurity.com
Open sourcemalware.news
Open sourcekrebsonsecurity.com
Open sourcemalware.news
Open sourcebitsight.com
Open sourceic3.gov
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.